About this role
Position Summary
This role owns identity and access management (Okta and adjacent identity tooling) and Atlassian/Jira/Confluence platform administration as dedicated, full-time disciplines. It exists to create a specialist role who can get ahead of configurations, designing for scale, and closing any identity gaps (entitlement configurations, contractor and non-employee access, and access-automation).
Role Purpose
- Own identity and access management as a full-time discipline: SSO, entitlement governance, and access automation.
- Own Atlassian/Jira/Confluence as dedicated platform administration, including the ITDESK project that every team at Fetch depends on.
- Identify, propose and implement improvements.
- Get ahead of platform and identity risk through architecture and automation, rather than reacting to incidents after they occur.
- Provide senior technical depth that the current generalist model cannot sustain.
Key Responsibilities
1. Identity & Access Management (Okta)
- Own configuration and administration of Okta SSO, MFA policy, and lifecycle workflows (onboarding, offboarding, role changes).
- Own entitlement governance: design and run periodic access reviews, identify and remediate stale or excess access, and close gaps that allowed past entitlement misconfigurations.
- Own contractor and non-employee access governance, including time-bound access, approval workflows, and offboarding enforcement.
- Integrate and manage third-party application SSO connections; troubleshoot identity-related issues escalated from the team.
- Maintain security compliance for identity systems in partnership with Information Security.
2. Access Automation & Risk Reduction
- Build and maintain automated workflows for provisioning, deprovisioning, and access review (e.g., via Okta workflows, or adjacent automation tooling) to reduce manual access administration.
- Investigate and close automation gaps.
- Partner with Information Security on broader architectural patterns and help remediate patterns in IT-administered systems.
3. Atlassian Suite Platform Administration
- Own Jira project configuration, workflows, permission schemes, and automation rules.
- Administer Confluence spaces, permissions, and documentation standards.
- Support Bitbucket configuration and access where applicable.
- Design for scale and plan platform architecture proactively rather than administering reactively.
4. Platform & Identity Architecture
- Evaluate and recommend new tooling, integrations, or automation that improve identity governance or platform scalability.
- Maintain technical documentation for identity and platform systems sufficient for audit, onboarding, and incident response.
5. Cross-Functional Partnership
- Partner with Information Security on identity-related risk, audit evidence, and remediation of access-related findings.
- Partner with the Manager of IT Operations on prioritization, escalation, and coordination with the rest of the IT Operations team.
- Serve as the technical point of contact for identity and Atlassian platform questions across the company.
6. Documentation & Continuous Improvement
- Maintain clear, current documentation for identity workflows, access policies, and platform configuration.
- Identify recurring manual work in identity or platform administration and drive it toward automation or self-service.
- Contribute to access request, approval, and audit workflow improvements.
Decision Rights
Within established security and platform standards, this role is authorized to:
- Configure and modify Okta and Atlassian platform settings within approved change-management practices.
- Design and implement access automation workflows.
- Recommend and prioritize platform architecture changes.
- Flag and pause changes that present apparent identity or platform risk pending review.
Required Qualifications
- Ability to work onsite as needed to provide hands-on IT support to Fetch team members in our Madison, Chicago, Boston, or New York offices.
- 5+ years in IT engineering or systems administration with a concentration in identity and access management and/or SaaS platform administration.
- Direct hands-on experience administering Okta in a production environment, including SSO, MFA, and lifecycle automation.
- Direct experience administering Atlassian tools (Jira, Confluence) at an organizational scale, including workflow and permission design.
- Working knowledge of SAML/SSO concepts and access governance practices.
- Familiarity with scripting, automation tooling, and API/webhook-based integrations.
- Strong documentation habits and ability to work independently on platform architecture decisions.
Preferred Qualifications
- Experience remediating identity-related security incidents or entitlement misconfigurations.
- Experience with JumpCloud, Google Workspace admin, or AWS IAM.
- Experience designing access review or automated deprovisioning programs.
- B.S. in Computer Science, Information Systems, or equivalent experience.
- Relevant certifications (Okta Certified Administrator, Atlassian certifications, or equivalent).
Core Competencies
- Deep technical ownership of high-blast-radius systems
- Proactive risk identification and architecture-first thinking
- Automation-first problem solving
- Independent judgment and prioritization
- Cross-functional partnership with Security and IT leadership
- Documentation discipline
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?